Edge Copy setup link
Skill evidence / analyzing-mft-for-deleted-file-recovery
Skill profile

analyzing-mft-for-deleted-file-recovery

Analyze the NTFS Master File Table ($MFT) with MFTECmd.

What this skill does for you

Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT, and X-Ways Forensics to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space. Use when recovering evidence of deleted files, reconstructing NTFS file-system timelines, or detecting anti-forensic timestomping during a Windows forensic examination.

Quoted from the skill description in the pinned source

Who made it

Publishermukul975
Installs342as of Sep 27, 2026

Use it with Edge

Set up Edge for me: read getedge.cc/SKILL.md and follow it. Then use Edge to load the analyzing-mft-for-deleted-file-recovery skill from mukul975/anthropic-cybersecurity-skills.

Paste it into Claude, ChatGPT, Codex or Cursor.

Or read the skill source first.

Security evidence

Security state at 2026-09-30: reviewed. State definitions. This records static evidence for this revision; live load eligibility is checked again.

3 static scans, 0 counted findings. The listed scanners recorded the results shown for this package revision.

ScannerDateResultFindings
Edge static checks2026-09-27Pass0
Cisco skill-scanner2026-09-27Pass0
Semgrep Edge rules2026-09-27Pass0

Static scans check the code, not how well the skill works.

Scanner scope, raw findings and mirrored provider records

Edge static checks (Edge-run): edge-static/1.0.1. Scope: Static patterns for remote execution, credentials with network sends, obfuscation, prompt overrides, hidden Unicode, binaries and persistence. Revision: 54a798831d2266a3ca61ce68a7acb80b81160d57. Raw findings: . Counted findings: .

Cisco skill-scanner (Edge-run): cisco-skill-scanner/2.1.0. Scope: Local static, YARA, pipeline and behavioral analyzers; no LLM or AI Defense analysis. Revision: 54a798831d2266a3ca61ce68a7acb80b81160d57. Raw findings: . Counted findings: .

Semgrep Edge rules (Edge-run): semgrep/1.178.0+edge-rules.c15016a36fd3+offline-v1. Scope: Six Edge-authored static rules with Semgrep CE; offline execution and metrics disabled. Semgrep-maintained rules excluded. Revision: 54a798831d2266a3ca61ce68a7acb80b81160d57. Raw findings: . Counted findings: .

Source and licence

Repository
https://github.com/mukul975/anthropic-cybersecurity-skills
Pinned skill file
View source at revision
Revision
54a798831d2266a3ca61ce68a7acb80b81160d57
Package hash
sha256:e2344448c84d4be0cfcd1cf8dafa532579aead4ef46d2fc439133c35dfbe2ce3
Licence
Apache-2.0